Best practices
When it comes to capturing and analyzing network traffic, there are no hard and fast best practices; however, I would like to share some insights that helped me along my career:
- Stick to the basics: When you analyze network traffic, it is imperative that you know how networking works. Many of the network capturing tools today will provide you with great dashboards and insight into the packets. However, you still need to know about the types of network traffic. Think about authentication traffic. If you are targeting RADIUS authentication, you need to know how RADIUS works. The same applies to Active Directory and so forth. Having a good understanding of networking will help you ensure that you are working with the right data packets, and ultimately, it will equip you for success.
- Keep an eye on your capture size: While performing a packet capture on a busy network, the size of your capture file can grow exponentially. At times, you may need to limit the number...